1
00:00:06,480 --> 00:00:09,646
- Welcome to Lesson 9, Deep Dive Quiz.

2
00:00:09,646 --> 00:00:10,860
Now, Lesson 9 was all about explaining

3
00:00:10,860 --> 00:00:12,570
the purpose of mitigation techniques

4
00:00:12,570 --> 00:00:15,190
that we use to secure the enterprise.

5
00:00:15,190 --> 00:00:16,470
And we looked at two lessons:

6
00:00:16,470 --> 00:00:19,140
9.1, Secure Design Principles

7
00:00:19,140 --> 00:00:22,440
and Lesson 9.2, Segmentation.

8
00:00:22,440 --> 00:00:24,570
So now we're gonna do
five questions together.

9
00:00:24,570 --> 00:00:27,120
I hope you have a piece of
paper and a pen or pencil.

10
00:00:27,120 --> 00:00:28,710
'cause just like before,

11
00:00:28,710 --> 00:00:30,090
I want you to put me on pause,

12
00:00:30,090 --> 00:00:32,610
try to answer the question
the best you can, right?

13
00:00:32,610 --> 00:00:35,460
Then come on back and
hear the explanation.

14
00:00:35,460 --> 00:00:36,813
So let's start our quiz.

15
00:00:37,927 --> 00:00:41,610
"Devices in the security
zone connect to both trusted

16
00:00:41,610 --> 00:00:43,830
and untrusted environments."

17
00:00:43,830 --> 00:00:46,950
Is this a screen subnet, a honeynet,

18
00:00:46,950 --> 00:00:50,310
an air-gapped network, or an enclave?

19
00:00:50,310 --> 00:00:52,320
So devices in the security zone

20
00:00:52,320 --> 00:00:54,810
connect to both untrusted
and trusted environments.

21
00:00:54,810 --> 00:00:56,550
Are we talking about a screened subnet,

22
00:00:56,550 --> 00:00:58,770
a honeynet, an air-gapped zone,

23
00:00:58,770 --> 00:01:00,750
or an enclave?

24
00:01:00,750 --> 00:01:01,600
What do you like?

25
00:01:03,358 --> 00:01:05,430
Well, I'm gonna choose a screened subnet.

26
00:01:05,430 --> 00:01:07,140
A screened subnet is going to connect

27
00:01:07,140 --> 00:01:09,360
to both the trusted and untrusted.

28
00:01:09,360 --> 00:01:10,770
And as I talked about in the lesson,

29
00:01:10,770 --> 00:01:12,990
we used to refer to it as a DMZ, right?

30
00:01:12,990 --> 00:01:17,100
A honeynet is just a
network of our honeypots.

31
00:01:17,100 --> 00:01:18,480
An air-gapped network

32
00:01:18,480 --> 00:01:21,870
is never going to connect
to an untrusted network

33
00:01:21,870 --> 00:01:25,380
or to any any network or device

34
00:01:25,380 --> 00:01:27,570
that connects to an untrusted network.

35
00:01:27,570 --> 00:01:32,088
And an enclave network is
going to be a trusted network

36
00:01:32,088 --> 00:01:33,330
within our trusted network.

37
00:01:33,330 --> 00:01:36,510
So I'm going with screen
subnet, let's check it out.

38
00:01:36,510 --> 00:01:37,533
And that's correct.

39
00:01:39,150 --> 00:01:40,237
Question two.

40
00:01:40,237 --> 00:01:43,980
"System architects are discussing
secure design principles

41
00:01:43,980 --> 00:01:47,070
including one, multiple
layers of controls,

42
00:01:47,070 --> 00:01:49,560
two, permission-based access controls,

43
00:01:49,560 --> 00:01:52,770
and three, privilege access management.

44
00:01:52,770 --> 00:01:54,960
Which principle in the list below there

45
00:01:54,960 --> 00:01:57,360
is not included in their discussion?"

46
00:01:57,360 --> 00:02:00,390
Least functionality, default deny,

47
00:02:00,390 --> 00:02:01,950
zero trust,

48
00:02:01,950 --> 00:02:04,350
or defense-in-depth.

49
00:02:04,350 --> 00:02:07,500
So they're talking about
multiple layers of control,

50
00:02:07,500 --> 00:02:10,200
they're talking about
permission-based access,

51
00:02:10,200 --> 00:02:13,923
and they're talking about
privileged access management.

52
00:02:14,910 --> 00:02:16,743
So what's not really included?

53
00:02:19,650 --> 00:02:21,240
Well, let's go through it.

54
00:02:21,240 --> 00:02:23,160
So multiple layers of control.

55
00:02:23,160 --> 00:02:24,690
Well, that would be defense-in-depth,

56
00:02:24,690 --> 00:02:26,490
they're talking about that.

57
00:02:26,490 --> 00:02:29,010
Permission-based access control,

58
00:02:29,010 --> 00:02:30,600
that's gonna be default deny,

59
00:02:30,600 --> 00:02:33,633
where there is no access
until you get permission.

60
00:02:35,137 --> 00:02:36,540
And privilege access management,

61
00:02:36,540 --> 00:02:39,300
that is one of the
supporting things that we do

62
00:02:39,300 --> 00:02:41,580
for a zero-trust environment.

63
00:02:41,580 --> 00:02:43,380
What we don't see anything here

64
00:02:43,380 --> 00:02:45,090
is about least functionality.

65
00:02:45,090 --> 00:02:46,740
Least functionality is ensuring

66
00:02:46,740 --> 00:02:49,800
that there's no unnecessary open ports

67
00:02:49,800 --> 00:02:53,280
or protocols or services or applications

68
00:02:53,280 --> 00:02:54,240
in a device, right?

69
00:02:54,240 --> 00:02:57,370
We're trying to have a
small footprint, right?

70
00:02:57,370 --> 00:02:59,730
And as small as attack
surface as possible.

71
00:02:59,730 --> 00:03:04,050
So what we don't see here
would be least functionality.

72
00:03:04,050 --> 00:03:05,640
Do you agree?

73
00:03:05,640 --> 00:03:06,603
Let's check it out.

74
00:03:07,440 --> 00:03:09,210
And that's correct.

75
00:03:09,210 --> 00:03:10,777
All right. Question three.

76
00:03:10,777 --> 00:03:13,740
"Micro-segmentation allows
for the implementation

77
00:03:13,740 --> 00:03:16,770
of zero-trust protect
surface environments.

78
00:03:16,770 --> 00:03:19,110
Which statement is not true?"

79
00:03:19,110 --> 00:03:21,330
Not, again, that important word,

80
00:03:21,330 --> 00:03:24,000
not true about zero-trust
protect surfaces.

81
00:03:24,000 --> 00:03:25,950
That means three of
these statements are true

82
00:03:25,950 --> 00:03:27,600
and one is not.

83
00:03:27,600 --> 00:03:29,970
It supports standing privilege.

84
00:03:29,970 --> 00:03:32,130
It's always knowable.

85
00:03:32,130 --> 00:03:34,230
It's orders of magnitude smaller

86
00:03:34,230 --> 00:03:36,183
than the enterprise attack surface,

87
00:03:37,020 --> 00:03:39,753
and it incorporates the
network's most critical DAAS.

88
00:03:41,580 --> 00:03:43,350
So which statement is not true

89
00:03:43,350 --> 00:03:45,453
about a zero-trust protect surface?

90
00:03:47,520 --> 00:03:49,660
But let's start on the bottom.

91
00:03:49,660 --> 00:03:52,800
It does incorporate the
network's most critical DAAS.

92
00:03:52,800 --> 00:03:55,623
It obviously, a protect surface obviously

93
00:03:55,623 --> 00:03:58,410
is always gonna be magnitudes smaller

94
00:03:58,410 --> 00:04:00,930
than the enterprise attack surface.

95
00:04:00,930 --> 00:04:02,580
It's always knowable, right?

96
00:04:02,580 --> 00:04:04,893
Because it's your most valuable assets.

97
00:04:05,760 --> 00:04:07,230
Ah, here's what it doesn't do.

98
00:04:07,230 --> 00:04:09,090
It doesn't support standing privilege.

99
00:04:09,090 --> 00:04:10,260
What is standing privilege?

100
00:04:10,260 --> 00:04:13,140
Standing privilege means that
you have always on access.

101
00:04:13,140 --> 00:04:15,060
If you are a network administrator

102
00:04:15,060 --> 00:04:16,320
and you have full admin rights,

103
00:04:16,320 --> 00:04:18,420
well, that means you always, always

104
00:04:18,420 --> 00:04:20,340
have those full admin
rights all the time, right?

105
00:04:20,340 --> 00:04:22,020
That would be standing privilege.

106
00:04:22,020 --> 00:04:24,210
In a zero-trust environment, right,

107
00:04:24,210 --> 00:04:26,640
it's really the opposite of
standing privilege, right?

108
00:04:26,640 --> 00:04:28,260
We're not giving you standing privilege.

109
00:04:28,260 --> 00:04:29,628
Matter of fact,

110
00:04:29,628 --> 00:04:31,710
you are going to be
required to reauthenticate

111
00:04:31,710 --> 00:04:33,030
over and over and over again

112
00:04:33,030 --> 00:04:35,310
and only be given the rights
and permissions you need

113
00:04:35,310 --> 00:04:36,933
for a limited period of time.

114
00:04:37,860 --> 00:04:40,770
So what is not true is that it
supports standing privilege.

115
00:04:40,770 --> 00:04:42,300
Do you like that one?

116
00:04:42,300 --> 00:04:43,133
Okay.

117
00:04:44,460 --> 00:04:45,690
And that's correct.

118
00:04:45,690 --> 00:04:47,220
Let's go on to question four.

119
00:04:47,220 --> 00:04:48,120
This is a matching one,

120
00:04:48,120 --> 00:04:49,920
so you're definitely gonna
need to put me on pause

121
00:04:49,920 --> 00:04:51,480
while you work through this.

122
00:04:51,480 --> 00:04:53,160
We're gonna match the security principles

123
00:04:53,160 --> 00:04:54,480
and the discussions.

124
00:04:54,480 --> 00:04:57,690
Least functionality, survivability,

125
00:04:57,690 --> 00:05:00,360
least privilege, and default deny.

126
00:05:00,360 --> 00:05:01,980
Now, be careful here
'cause it's really easy

127
00:05:01,980 --> 00:05:05,790
to confuse least functionality
and least privilege.

128
00:05:05,790 --> 00:05:08,610
On the right-hand side, we
have that the system property

129
00:05:08,610 --> 00:05:12,573
that access is not allowed
unless specifically specified.

130
00:05:13,590 --> 00:05:15,990
Removing unnecessary services, protocols,

131
00:05:15,990 --> 00:05:18,750
applications, et cetera, from an object,

132
00:05:18,750 --> 00:05:21,903
or assigning minimal rights
and permissions to a subject.

133
00:05:22,830 --> 00:05:25,480
So put me on pause, match
them up, then come on back.

134
00:05:26,490 --> 00:05:27,600
All right, let's start with the first one,

135
00:05:27,600 --> 00:05:29,430
a system property.

136
00:05:29,430 --> 00:05:31,830
Well, the one in the list
here would be survivability.

137
00:05:31,830 --> 00:05:34,620
Survivability is a system property.

138
00:05:34,620 --> 00:05:38,880
Access not allowed unless
specifically specified.

139
00:05:38,880 --> 00:05:41,670
Ah, that sounds a lot like
a default deny posture.

140
00:05:41,670 --> 00:05:45,420
There's no access allowed
until we specifically allow it.

141
00:05:45,420 --> 00:05:47,550
All right, now we're left
with least functionality

142
00:05:47,550 --> 00:05:49,020
and least privilege.

143
00:05:49,020 --> 00:05:52,470
One applies to objects,
one applies to subjects.

144
00:05:52,470 --> 00:05:56,010
So assigning minimal rights
and permissions to a subject,

145
00:05:56,010 --> 00:05:58,443
that's gonna be least privilege.

146
00:05:59,460 --> 00:06:01,993
And removing unnecessary services,

147
00:06:01,993 --> 00:06:04,170
protocols, and applications
from an object,

148
00:06:04,170 --> 00:06:07,560
that's gonna be our principle
of least functionality.

149
00:06:07,560 --> 00:06:08,850
So least functionality,

150
00:06:08,850 --> 00:06:10,530
removing unnecessary services,

151
00:06:10,530 --> 00:06:12,690
protocols, and applications
from an object,

152
00:06:12,690 --> 00:06:15,510
survivability, which is a system property.

153
00:06:15,510 --> 00:06:16,983
Least privilege,

154
00:06:16,983 --> 00:06:18,000
which is assigning minimal
rights and permissions

155
00:06:18,000 --> 00:06:19,701
to a subject,

156
00:06:19,701 --> 00:06:21,630
and default deny where
access is not allowed

157
00:06:21,630 --> 00:06:24,240
unless explicitly specified.

158
00:06:24,240 --> 00:06:25,740
Do you agree? Do you like it?

159
00:06:25,740 --> 00:06:26,763
Let's check it out.

160
00:06:28,759 --> 00:06:29,592
And that is correct.

161
00:06:29,592 --> 00:06:31,230
Awesome. Let's move on.

162
00:06:31,230 --> 00:06:32,977
This is our last question.

163
00:06:32,977 --> 00:06:35,100
"You're meeting with the SecDevOps team

164
00:06:35,100 --> 00:06:37,650
and discussing secure design options.

165
00:06:37,650 --> 00:06:40,110
Now, the goal is to create
protection mechanisms

166
00:06:40,110 --> 00:06:42,180
that users routinely apply

167
00:06:42,180 --> 00:06:45,060
and they rarely attempt to circumvent.

168
00:06:45,060 --> 00:06:47,580
Which principle best describes this goal?"

169
00:06:47,580 --> 00:06:49,200
An open design,

170
00:06:49,200 --> 00:06:50,760
separation of duties,

171
00:06:50,760 --> 00:06:52,950
securing the weakest link,

172
00:06:52,950 --> 00:06:55,170
or psychological acceptance?

173
00:06:55,170 --> 00:06:56,460
If you need to put me on pause

174
00:06:56,460 --> 00:06:58,080
while you read through those again.

175
00:06:58,080 --> 00:07:00,720
But our goal is to create
protection mechanisms

176
00:07:00,720 --> 00:07:03,180
that users routinely apply, right?

177
00:07:03,180 --> 00:07:06,120
They're cool with it and
they rarely attempt, if ever,

178
00:07:06,120 --> 00:07:08,730
hopefully never, attempt to circumvent it.

179
00:07:08,730 --> 00:07:11,100
So what principle are we talking about?

180
00:07:11,100 --> 00:07:12,330
Open design,

181
00:07:12,330 --> 00:07:13,320
separation of duties,

182
00:07:13,320 --> 00:07:15,060
secure the weakest link,

183
00:07:15,060 --> 00:07:17,430
or psychological acceptance?

184
00:07:17,430 --> 00:07:21,540
Well, open design means that
the security of the design

185
00:07:21,540 --> 00:07:23,670
shouldn't depend on being hidden, right?

186
00:07:23,670 --> 00:07:26,250
It's open. You can see what it is.

187
00:07:26,250 --> 00:07:29,970
Really, our response is idea
of security through obscurity.

188
00:07:29,970 --> 00:07:32,370
Separation of duties,
I gave you that example

189
00:07:32,370 --> 00:07:34,410
when we talked about the wire transfer

190
00:07:34,410 --> 00:07:37,920
where user A could create the vendor,

191
00:07:37,920 --> 00:07:39,180
user B could create the payment,

192
00:07:39,180 --> 00:07:40,830
and user C would authorize it.

193
00:07:40,830 --> 00:07:45,830
The idea is that we separate
a duty into smaller tasks

194
00:07:46,170 --> 00:07:48,150
and no one person, no one subject

195
00:07:48,150 --> 00:07:49,050
is in complete control

196
00:07:49,050 --> 00:07:51,750
or has complete decision-making powers.

197
00:07:51,750 --> 00:07:52,860
Securing the weakest link,

198
00:07:52,860 --> 00:07:55,500
well, that's just what it sounds like.

199
00:07:55,500 --> 00:07:57,780
I'm going with this one.
Psychological acceptance.

200
00:07:57,780 --> 00:08:00,030
It's all about how the user

201
00:08:00,030 --> 00:08:02,250
perceives those protection mechanisms.

202
00:08:02,250 --> 00:08:04,350
We wanna make it easy
and comfortable for them,

203
00:08:04,350 --> 00:08:05,250
not inconvenient.

204
00:08:05,250 --> 00:08:07,110
We want them to routinely apply

205
00:08:07,110 --> 00:08:08,677
and we don't want them to say,

206
00:08:08,677 --> 00:08:10,800
"Oh, I'm gonna circumvent
that. I'm gonna get around it."

207
00:08:10,800 --> 00:08:13,800
So that would be the principle
of psychological acceptance.

208
00:08:13,800 --> 00:08:16,200
Agree? We'll check it out.

209
00:08:16,200 --> 00:08:17,193
And it's correct.

210
00:08:18,450 --> 00:08:19,770
Congratulations. Great job.

211
00:08:19,770 --> 00:08:21,480
I hope you got them all right.

212
00:08:21,480 --> 00:08:23,940
Up next, we're gonna move into Module 3,

213
00:08:23,940 --> 00:08:26,290
which is Security Architecture.

214
00:08:26,290 --> 00:08:28,200
And we're gonna start with Lesson 10

215
00:08:28,200 --> 00:08:30,960
to compare and contrast
security implications

216
00:08:30,960 --> 00:08:32,910
of different architecture models.

217
00:08:32,910 --> 00:08:34,010
So I'll see you there.
